Back to skill

Security audit

Libtv Api Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward LibLib.tv media-generation guide, with disclosed account login, upload, and download behavior.

Install only if you intend to use LibLib.tv and trust the external @libtv/skills npm package. Review prompts and uploaded images before running generation commands, because the workflow uses your LibLib account token and may upload files to the service.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger examples include very broad natural-language phrases such as “做动画”, “画一个 xxx”, and “来段 xxx”, which are common everyday requests and can cause the skill to be invoked unintentionally. In an agent ecosystem, over-broad invocation increases the chance that user content or unrelated conversations are routed into this skill, potentially causing unintended API calls, file uploads, or media-generation actions tied to the user's authenticated LibLib account.

Static analysis

No suspicious patterns detected.